PentestOps
  • Home
  • Solutions
    Solutions
    Enterprise Pentesting Continuous Pentesting AI Pentesting Automated Pentesting Web App Pentesting API Pentesting External Network Testing Internal Network Testing
     
    Cloud Pentesting AWS Pentesting Azure Pentesting GCP Pentesting Kubernetes Security Active Directory Security M365 Security EASM Exposure Management Vulnerability Management Integrations MSP Security Platform
    Industries
    Healthcare Financial Services Government Education Manufacturing Retail and eCommerce All industries All solutions
  • Features
  • Agent
  • Pricing
  • Resources
    Knowledge Centre
    What Is Penetration Testing? Continuous Penetration Testing AI in Penetration Testing PTES Explained OWASP Top 10 NIST SP 800-115 All articles
    More
    Methodology Vendor Comparison Release Notes Open-Source Tools
  • Methodology
  • Comparison
  • About
  • Contact
Login Sign Up Free Demo
Legal Document

Data Processing Addendum

Extranet Systems Pty Ltd (ABN 29 632 743 189). Last updated: June 2026.

Overview

This page sets out the terms of the PentestOps Data Processing Addendum (DPA), including our roles, sub-processors, international transfers, security measures, breach notification, audit rights, and return and deletion of data. The DPA governs how Extranet Systems Pty Ltd processes personal data on behalf of our customers when they use PentestOps, and supplements our Terms of Service and Privacy Policy.

Requesting the DPA

A signable DPA is available to customers on request. Please email privacy@pentestops.ai or legal@pentestops.ai and we will provide the current version for execution.

Controller and processor roles

For personal data you submit to PentestOps, the roles are as follows:

  • You (the customer) act as the data controller. You decide what data is processed and for what purpose, and you are responsible for having a lawful basis and the necessary authorisation to scan your targets.
  • Extranet Systems acts as the data processor. We process personal data only on your documented instructions to provide and support the service.

We process data for the limited purposes of delivering security testing, generating reports, and supporting your account, and we apply the technical and organisational measures described in our Trust Centre.

Sub-processors

We engage a small number of vetted sub-processors to deliver the service, each bound by contract to protect personal data. Our current sub-processors and their purposes are listed in our Trust Centre. We will give customers notice of material changes so they can raise any reasonable objection.

International data transfers

Where personal data is transferred outside its country of origin, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), to provide a lawful basis for the transfer. Region details and data-residency options for Enterprise customers are described in our Trust Centre.

Security measures

We implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include:

  • Encryption. Customer data is encrypted at rest, and all traffic is protected with TLS in transit.
  • Tenant isolation. Every customer runs in an isolated Kubernetes namespace with its own dedicated database. There is no shared tenant data store.
  • Access control. Role-based access control, with multi-factor authentication available on every account and required for administrators.
  • Secrets management. Credentials and signing keys are held in a dedicated secrets vault and injected at runtime, never committed to source.
  • Logging. A tamper-evident audit log is retained for 365 days.
  • Certification. Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. A copy of the certificate is available on request.

The current measures are described in more detail in our Trust Centre. We may update them over time provided the overall level of protection is not reduced.

Personal data breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, so that you can meet your own regulatory notification obligations as controller.

Our notification will, to the extent known at the time, describe:

  • the nature of the breach, including the categories and approximate number of data subjects and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address it and to mitigate its effects; and
  • a contact point for further information.

Where the full picture is not available immediately, we will provide information in phases as the investigation progresses rather than delaying the initial notification. We will also reasonably assist you in meeting your obligations to notify supervisory authorities and affected individuals.

Audit rights

We will make available the information reasonably necessary to demonstrate our compliance with our obligations as processor, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

  • Documentation first. In most cases our ISO/IEC 27001:2022 certification and supporting documentation will satisfy an audit request, and we will provide these on request.
  • On-request audits. Where that is not sufficient for your regulatory obligations, audits may be carried out on reasonable prior written notice, during business hours, no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach.
  • Scope limits. Audits must not compromise the security, confidentiality or availability of other customers' data, and the auditor must be bound by appropriate confidentiality obligations.

Return and deletion of data

Assessment findings and scan data are retained according to your plan, then deleted automatically:

  • Starter: 1 year
  • Professional: 3 years
  • Enterprise and MSP: up to 7 years, with custom retention available

On termination or expiry of your subscription, we will delete or return personal data processed on your behalf at your choice, except where we are required by law to retain it. Exported reports, signed authorisation records and legal documents are kept as records of the engagement and are not removed by the routine retention process. Findings can be placed on legal hold where you need them preserved.

Details of processing

  • Subject matter and duration. Provision of the PentestOps platform for the term of your subscription, plus the retention period above.
  • Nature and purpose. Security testing, vulnerability and exposure management, exploit validation, remediation guidance and reporting.
  • Types of personal data. Account and contact details of your authorised users; and any personal data incidentally present in scan targets, findings or evidence generated during testing of your systems.
  • Categories of data subjects. Your personnel and authorised users, and any individuals whose data appears incidentally in the systems you authorise us to test.
  • Assistance. Taking into account the nature of the processing, we will assist you with data subject requests and with your obligations on security, breach notification and data protection impact assessments.

We process personal data only on your documented instructions, and personnel authorised to access it are bound by confidentiality obligations.

Contact

For DPA requests, sub-processor questions, or data-protection enquiries, please contact us:

Extranet Systems Pty Ltd - Privacy & Legal

Privacy: privacy@pentestops.ai

Legal: legal@pentestops.ai

Trust Centre: pentestops.com/security

PentestOps

Enterprise-grade penetration testing platform by Extranet Systems. Secure your digital assets with advanced security assessments and comprehensive vulnerability testing.

pentestops.com

+61 1300 290 196

info@pentestops.ai

Product

  • Features
  • On-Prem Agent
  • Pricing
  • Comparison
  • API

Solutions

  • Enterprise Pentesting
  • Continuous Pentesting
  • AI Pentesting
  • Automated Pentesting
  • Web App Pentesting
  • API Pentesting
  • All Solutions
  • By Industry

Resources

  • Knowledge Centre
  • Sample Report
  • Methodology
  • PentestOps vs Pentera
  • PentestOps vs Horizon3.ai NodeZero
  • PentestOps vs Cobalt
  • Release Notes
  • Open-Source Tools
  • Support

Company

  • About Us
  • Careers
  • Contact
  • Partners

Legal

  • Privacy Policy
  • Terms of Use
  • Trust Centre
  • DPA
  • Free Demo Scan
Penetration testing across: Australia Sydney Melbourne Brisbane Canberra New Zealand

© 2026 Extranet Systems Pty Ltd (ABN 29 632 743 189), Wollongong NSW, Australia. All rights reserved. | PentestOps is a security platform operated by Extranet Systems.